Privacy & Cookie Policy
This is the English version of our privacy policy. Dansk version her.
| Data controller | Mit Beredskab ApS, CVR 42299529 |
| Contact | kontakt@mitberedskab.dk |
| Website | https://mitberedskab.dk [Bekræftet 29. mar. 2026] |
| Version | 1.4 |
| Created | 2026-02-11 |
| Last updated | 2026-08-21 |
Section 1. Introduction and scope
This privacy and cookie policy describes how Mit Beredskab ApS (hereinafter “MitBeredskab”, “we”, “us” or “our”) collects, processes and protects personal data when you visit our website mitberedskab.dk, contact us, or otherwise interact with us as a potential or existing customer.
This policy covers: The website mitberedskab.dk, including contact forms, web analytics, cookies, sales, marketing, customer administration and contract conclusion. In these contexts, MitBeredskab is the data controller.
This policy does not cover: The web application app.mitberedskab.dk and the associated mobile app. Use of the alerting app is subject to a separate and enhanced data processing agreement entered into directly between MitBeredskab and the individual organisational customer (school, municipality or company) pursuant to GDPR Article 28. In this context, MitBeredskab acts as a data processor, and the organisation is the data controller for the personal data processed in the app. If you have questions about how your data is processed in the app, please contact your workplace or school.
Section 2. Data controller and contact information
The data controller for the processing of personal data described in this policy is:
Mit Beredskab ApS CVR: 42299529 Niels Jernes Vej 10, 9220 Aalborg Øst, Denmark Email: kontakt@mitberedskab.dk Website: https://mitberedskab.dk [Bekræftet 29. mar. 2026]
We have not currently appointed a Data Protection Officer (DPO), but enquiries about personal data are handled with the highest priority.
Section 3. What personal data do we process?
| Situation | Data | Purpose |
|---|---|---|
| You visit the website | IP address (anonymised), page views, device type | Web analytics and website improvement (only with consent) |
| You fill in the contact form | Name, email, company, message | Responding to your enquiry |
| You become a customer (CRM) | Name, email, phone, company, company address, correspondence | Sales, invoicing and customer administration |
| You sign an agreement | Name, email, IP address, signature | Digital signing of contracts via BoldSign |
3.1 What we do not collect
We do not collect location data, health information, national identification numbers (CPR) or other special categories of personal data via the website.
Section 4. Purpose and legal basis
| Purpose | Legal basis | Legitimate interest (if applicable) |
|---|---|---|
| Responding to enquiries | Art. 6(1)(b): pre-contractual measures | – |
| Sales, invoicing and CRM | Art. 6(1)(b): performance of contract | – |
| Digital signing of agreements | Art. 6(1)(b): performance of contract | – |
| Web analytics (Google Analytics) | Art. 6(1)(a): consent | – |
| Remarketing and advertising (Facebook, LinkedIn, Google Ads) | Art. 6(1)(a): consent | – |
| Technical operation and debugging | Art. 6(1)(f): legitimate interest | Ensuring system stability and availability, which is critical for an alerting service |
| Direct marketing to existing customers | Art. 6(1)(f): legitimate interest | Information about relevant product updates and security improvements. You can always unsubscribe. |
| Automation of internal workflows | Art. 6(1)(f): legitimate interest | Efficient and secure handling of customer data between our systems |
Section 5. Recipients and sub-processors
We do not disclose personal data to third parties for their own purposes. We use the following sub-processors as part of our operations:
| Service | Provider | Purpose | Location |
|---|---|---|---|
| Hosting | Scaleway (SCW) | Server infrastructure and email | EU (France) |
| Web analytics | Google Analytics | Traffic analysis on mitberedskab.dk | EU/USA* |
| CRM | Pipedrive | Sales and customer administration | EU (Estonia/Ireland) |
| Contact form | Fillout.com (Restly, Inc.) | Receiving enquiries via the website | USA* |
| Digital signing | BoldSign (Syncfusion, Inc.) | Signing contracts and agreements | EU (Netherlands)** |
| Automation | Make.com (Celonis SE) | Automation of workflows between systems | EU*** |
| Internal communication | Google Workspace | Email and document sharing (internal) | EU/USA* |
| AI tools | Amazon Web Services (Bedrock) | AI-assisted preparation of documents and communications | EU (Frankfurt)**** |
| Live chat | Crisp IM SARL | Customer support via the website chat window (loads only on click) | EU (France) |
| Remarketing | Meta Platforms (Facebook Pixel) | Advertising and remarketing on Facebook/Instagram | EU/USA***** |
| Remarketing | LinkedIn (Insight Tag) | Advertising and remarketing on LinkedIn | EU/USA***** |
| Remarketing | Google Ads (Conversion Tracking) | Advertising and remarketing on Google | EU/USA***** |
* Third-country transfers (Google and Fillout): Google LLC and Fillout.com (Restly, Inc.) are certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission has approved as providing an adequate level of protection (adequacy decision of 10 July 2023). Fillout.com also uses the European Commission’s Standard Contractual Clauses (SCC) as a supplementary transfer mechanism.
** BoldSign: BoldSign offers EU data residency with a data centre in the Netherlands. Our account is configured with the EU as data location, so documents and personal data are stored and processed within the EU.
*** Make.com: Make.com (owned by Celonis SE, Germany) is ISO 27001-certified and DPF-certified. Our account uses an EU data centre. Celonis SE uses Standard Contractual Clauses (SCC) for any transfers to sub-processors outside the EU.
**** Amazon Web Services (Bedrock): We use AI tools via Amazon Web Services (AWS) with a data centre in the EU (Frankfurt). Personal data is processed exclusively on European servers. Data is not retained by the AI provider after processing (zero data retention) and is not used for training AI models.
***** Meta, LinkedIn and Google Ads: Meta Platforms Ireland Ltd., LinkedIn Ireland Unlimited Company and Google LLC are all certified under the EU-U.S. Data Privacy Framework (DPF). Remarketing cookies and pixels are activated only after your active consent via our cookie banner.
Section 6. Transfers to third countries
Our primary infrastructure is located in the EU (Scaleway in France, BoldSign in the Netherlands, Make.com in the EU, Pipedrive in Estonia/Ireland). No transfer of this data to countries outside the EU/EEA takes place.
For services provided by Google (Analytics, Ads, Workspace), Meta (Facebook), LinkedIn and Fillout.com, transfers to the USA may occur. These transfers are protected by the EU-U.S. Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses, cf. Section 5 above. Should the DPF framework be invalidated, we will immediately implement alternative transfer mechanisms or switch to EU-based alternatives.
Section 7. Retention period
- Contact form enquiries: Deleted no later than 12 months after the conclusion of the enquiry, unless a customer relationship has been established.
- CRM data (Pipedrive): Retained for as long as the customer relationship is active. Upon termination, data is deleted no later than 12 months afterwards, unless legislation requires longer retention (e.g. the Danish Bookkeeping Act: 5 years).
- Signed documents (BoldSign): Retained for as long as necessary for the contractual relationship and any legal requirements.
- Web analytics data (Google Analytics): Retained for up to 14 months, after which data is automatically anonymised.
- Marketing cookies (Facebook, LinkedIn, Google Ads): Cookies expire automatically after up to 2 years depending on the provider. Data is deleted by the provider in accordance with their respective data processing policies. Cookies are only activated with your consent.
Section 8. Your rights
As a data subject, you have the following rights under the GDPR:
| Right | Description |
|---|---|
| Access (Art. 15) | You have the right to obtain confirmation as to whether we process personal data about you and, if so, access to the data. |
| Rectification (Art. 16) | You have the right to have inaccurate data about you corrected. |
| Erasure (Art. 17) | In certain cases, you have the right to have data about you deleted. |
| Restriction (Art. 18) | In certain cases, you have the right to have the processing of your data restricted. |
| Data portability (Art. 20) | You have the right to receive your data in a structured, commonly used and machine-readable format. |
| Objection (Art. 21) | You have the right to object to processing based on legitimate interest, including direct marketing. |
| Withdrawal of consent | Where processing is based on consent (e.g. cookies), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. |
You can exercise your rights by contacting us at kontakt@mitberedskab.dk. We will respond to enquiries within 30 days.
Section 9. Complaint to the Danish Data Protection Agency
If you are dissatisfied with our processing of your personal data, you have the right to lodge a complaint with:
Datatilsynet (Danish Data Protection Agency) Carl Jacobsens Vej 35 2500 Valby, Denmark Phone: +45 33 19 32 00 Email: dt@datatilsynet.dk Website: https://www.datatilsynet.dk [Bekræftet 29. mar. 2026]
We encourage you to contact us first so that we can attempt to resolve any disagreements directly.
Section 10. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure, cf. GDPR Article 32. Our measures include:
- Encryption in transit: All communication between users and our systems is encrypted with TLS/SSL.
- Encryption at rest: Data is encrypted at server level by our hosting providers.
- Access control: Access to personal data is restricted to authorised employees following the principle of least privilege.
- Confidentiality: All employees with access to personal data are subject to confidentiality obligations.
- Ongoing evaluation: We regularly assess and update our security measures.
In the event of a personal data breach, we will notify the Danish Data Protection Agency within 72 hours in accordance with GDPR Article 33. If the breach poses a high risk to those affected, they will also be notified directly, cf. Article 34.
Section 11. Automated decision-making
We do not carry out automated decision-making, including profiling, which has legal effects or similarly significantly affects data subjects, cf. GDPR Article 22.
Section 12. Is it mandatory or voluntary to provide personal data?
Providing information via the contact form is voluntary but necessary for us to respond to your enquiry. Providing information in connection with contract conclusion (including digital signing) is a contractual prerequisite for the delivery of our services.
Section 13. Cookie policy
13.1 What are cookies?
Cookies are small text files stored on your device when you visit a website. They are used to make the website function correctly and to collect statistics about the use of the website.
13.2 Cookies on mitberedskab.dk
| Cookie name | Provider | Type | Lifetime | Purpose |
|---|---|---|---|---|
| cookie-consent | Mit Beredskab | Necessary | 12 months | Remembers your cookie choice (stored in browser localStorage) |
| cookie-consent-meta | Mit Beredskab | Necessary | 12 months | Timestamp and version of your cookie choice |
| _ga | Google Analytics | Statistics | 2 years | Distinguishes between unique visitors |
| _ga_* | Google Analytics | Statistics | 2 years | Persists session state (GA4) |
| _gid | Google Analytics | Statistics | 24 hours | Distinguishes between users and records page views |
| crisp-client* | Crisp IM SARL | Necessary | Up to 6 months | Keeps your support conversation alive between page views |
| _fbp | Meta Platforms (Facebook Pixel) | Marketing | 3 months | Identifies browsers for Facebook advertising |
| _fbc | Meta Platforms (Facebook Pixel) | Marketing | 2 years | Stores click ID from Facebook ads |
| lastExternalReferrer | Meta Platforms (Facebook Pixel) | Marketing | Until deleted | Most recent external referrer for Facebook advertising |
| lastExternalReferrerTime | Meta Platforms (Facebook Pixel) | Marketing | Until deleted | Timestamp of the most recent external referral (Facebook advertising) |
| li_sugr | LinkedIn (Insight Tag) | Marketing | 3 months | Identifies browsers for LinkedIn advertising |
| UserMatchHistory | LinkedIn (Insight Tag) | Marketing | 30 days | LinkedIn Ads optimisation |
| bcookie | LinkedIn (Insight Tag) | Marketing | 1 year | Browser ID for the LinkedIn Insight Tag |
| lidc | LinkedIn (Insight Tag) | Marketing | 24 hours | Routing for the LinkedIn Insight Tag |
| _gcl_au | Google Ads (Conversion Tracking) | Marketing | 3 months | Stores conversion data from Google Ads |
The table covers both cookies proper and equivalent storage technologies (e.g. browser localStorage), which the Danish Cookie Executive Order treats alike. Names marked with \* cover a family of keys whose suffix varies.
Statistics and marketing cookies are only activated after your active consent via our cookie banner. You can change or withdraw your consent at any time via the cookie banner.
13.3 Legal basis for cookies
- Necessary cookies: Section 3(2) of the Danish Cookie Executive Order (exempt from consent requirement).
- Statistics cookies: GDPR Article 6(1)(a) (consent), cf. Section 3(1) of the Danish Cookie Executive Order.
- Marketing cookies: GDPR Article 6(1)(a) (consent), cf. Section 3(1) of the Danish Cookie Executive Order. Used for remarketing and advertising on Facebook, LinkedIn and Google.
13.4 How to delete cookies that have already been set
Withdrawing your consent via the cookie banner stops us from setting new cookies, but it does not automatically remove those already stored in your browser. You delete those yourself:
- Open your browser’s settings and find the privacy section (typically “Privacy and security” or “Clear browsing data”).
- Choose to delete cookies and site data for mitberedskab.dk, or for all websites. “Site data” also covers localStorage, which this policy treats on equal footing with cookies.
- The exact steps vary between browsers (Chrome, Safari, Firefox, Edge); search for “delete cookies” in your browser’s own help function for step-by-step instructions.
Note: deleting cookies also deletes your saved cookie choice, and the banner will appear again on your next visit.
Section 14. Changes to this policy
We may update this privacy and cookie policy from time to time. In the event of significant changes, we will inform you via a prominent notice on our website before the changes take effect. The date of the most recent update appears at the top of this document.
Section 15. Contact
If you have questions about this policy or our processing of personal data, please contact us:
Mit Beredskab ApS CVR: 42299529 Niels Jernes Vej 10, 9220 Aalborg Øst, Denmark Email: kontakt@mitberedskab.dk Website: https://mitberedskab.dk [Bekræftet 29. mar. 2026]
Changelog
| Version | Date | Change | Responsible |
|---|---|---|---|
| 1.0 | 2026-02-11 | Document created and published on mitberedskab.dk | Tobias (CTO) |
| 1.1 | 2026-03-04 | AI tools (AWS Bedrock) added as sub-processor in Section 5. Date updated | Anders (CEO) |
| 1.2 | 2026-03-05 | Marketing cookies (Facebook, LinkedIn, Google Ads) added in Sections 4, 5, 6, 7 and 13. Cookie banner updated with category consent | Anders (CEO) |
| 1.3 | 2026-08-19 | Crisp (live chat) added as sub-processor in Section 5 and to the cookie table in 13.2. Footnote marker corrected for Meta/LinkedIn/Google Ads. Cookie table updated for GA4 (_ga_*) and extended with consent, Crisp and LinkedIn keys. Consent now expires after 12 months, and a “Cookieindstillinger” control was added to the footer so consent can be withdrawn | Anders (CEO) |
| 1.4 | 2026-08-21 | The tables in Section 5 and 13.2 are now machine-generated from an internal register and automatically checked on every release, so they cannot diverge from the website’s actual behaviour. New deletion guide in 13.4. The live chat (Crisp) now loads only when you click the chat button yourself, never automatically. Consent is stamped with a version so it can be tied to the banner version that collected it. “Afvis alle” now carries the same visual weight as “Accepter alle” | Anders (CEO) |
For any change to this document: (1) update the version number in the header, (2) set “Last updated” to the date of change, (3) add a new line to this changelog, and (4) record the change in the folder’s Changelog.md.
This policy is governed by Danish law. In the event of any discrepancy between this English version and the Danish version, the Danish version shall prevail.